logo

Case study: How predictive shielding in Defender stopped GPO-based ransomware before it started

ID: 6dad82ea-2155-5256-86f3-87a7bd2f541a

STIX ID: report--6dad82ea-2155-5256-86f3-87a7bd2f541a

Feed Name: Microsoft Security

Threat Score
80/100

Date Published: 2026-03-23

Date Updated: 2026-04-28

Author: Microsoft Defender Security Research Team

...
...

Microsoft Defender disrupted a sophisticated, human-operated ransomware campaign targeting a large educational institution where attackers abused Group Policy Objects to disable protections and deploy ransomware via scheduled tasks and SMB; Defender's predictive shielding and attack disruption prevented GPO-based encryption across ~700 devices, blocked roughly 97% of attempted encryption, and contained remaining impact.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.